Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Head of Information Security (Deputy CISO) role.
Rezi rewrites your resume against NewDay's job description. Free.

Tailor your resume to this Head of Information Security (Deputy CISO) role.
Rezi rewrites your resume against NewDay's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Head of Information Security (Deputy CISO) posting at NewDay — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Head of Information Security (Deputy CISO) posting at NewDay — free, in seconds.
About the Role
NewDay is seeking a Deputy Chief Information Security Officer to shape, lead, and strengthen its enterprise-wide security capability. Reporting to the CISO, this senior operational leader will translate security strategy into priorities, measurable outcomes, and consistent execution across various security domains. This high-impact role offers significant enterprise visibility, requiring representation in senior forums and clear insight into cyber and technology risk, ensuring alignment with NewDay’s risk appetite, regulatory responsibilities, customer commitments, and commercial ambitions.
Responsibilities
- Lead the Information Security function, including teams, priorities, delivery, and culture.
- Act as the CISO’s delegate in executive, risk, governance, customer, supplier, and regulatory forums.
- Ensure the function has the appropriate operating model, capabilities, technology, and management information.
- Oversee the operational delivery of NewDay’s security strategy, focusing investment on reducing cyber and technology risk.
- Own the Information Security Management System and support alignment with ISO/IEC 27001:2022, NIST Cybersecurity Framework, and other standards.
- Maintain and improve security policies, standards, and controls.
- Support compliance with PCI DSS, UK GDPR, Data Protection Act 2018, and FCA expectations.
- Lead security monitoring, threat management, vulnerability management, incident response, and cyber preparedness.
- Maintain effective incident playbooks, escalation routes, exercises, and lessons-learned processes.
- Oversee the technology and security contribution to operational resilience, business continuity, disaster recovery, and cyber recovery.
- Drive improvements in security tooling, telemetry, automation, and operational efficiency.
- Own the technology and information risk framework, including appetite, assessment, quantification, treatment, and reporting.
- Ensure security risks and control effectiveness are clearly understood and transparent to decision-makers.
- Embed security into major technology change, cloud adoption, platform engineering, digital delivery, and supplier-led transformation.
- Partner with technology and engineering leaders to ensure secure-by-design delivery.
- Oversee third-party and supply-chain security risk.
- Coordinate internal and external assurance activities, including audits and regulatory engagement.
- Ensure findings, control gaps, and regulatory commitments have clear ownership and are delivered to the required standard.
- Lead NewDay’s approach to AI security and governance.
Requirements
- Established security leader with strategic judgment and operational delivery capabilities.
- Experience leading broad, multidisciplinary teams.
- Ability to provide credible, concise advice to executives and Board-level stakeholders.
- Significant experience leading a broad Information Security function within a regulated organisation (ideally financial services, consumer credit, cards, payments, or FinTech).
- Experience operating as a senior deputy to a CISO or in an equivalent enterprise security leadership position.
- Experience across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance, and operational resilience.
- Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, Data Protection Act 2018, and control frameworks like NIST.
- Solid understanding of technology risk, risk appetite, control effectiveness, and operational resilience.
- Experience leading security incidents, audits, assurance programmes, regulatory engagement, and senior-level reporting.
- Excellent judgment, communication, and influencing skills.
- Confidence to make clear decisions and build alignment across complex stakeholder groups.
- Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer or Auditor are valuable.
- Experience with Microsoft Azure security, AI governance, cyber insurance, supplier assurance, or major technology transformation is beneficial.
Skills
- Information Security
- Security Operations
- Governance, Risk, and Compliance (GRC)
- Security Architecture
- Security Engineering
- Identity Management
- Third-Party Security
- Resilience
- Assurance
- Cybersecurity Strategy
- Risk Management
- ISO/IEC 27001
- NIST Cybersecurity Framework
- PCI DSS
- UK GDPR
- Data Protection Act 2018
- FCA Regulations
- Incident Response
- Threat Management
- Vulnerability Management
- Operational Resilience
- Business Continuity
- Disaster Recovery
- Cyber Recovery
- Security Tooling
- Automation
- AI Security
- AI Governance
- Microsoft Azure Security
- Cyber Insurance
- Supplier Assurance
- Technology Transformation
Work Type
- Permanent
Experience Level
- Senior leadership
- Executive
About the Company
- NewDay is a company focused on enabling its customers, technology strategy, and commercial growth.
- They value all types of diversity and foster a vibrant, authentic working culture where colleagues can be their whole selves.
- They are committed to inclusivity in their job design and hiring processes, ensuring accessibility for people with disabilities or caring responsibilities.
Equal Opportunity
- NewDay is an equal opportunity employer.
- They do not discriminate on the basis of protected characteristics or identities.
- They ensure job descriptions are inclusive and support participation in the application and interview process for people with disabilities or caring responsibilities.
- They will implement reasonable adjustments to support candidates.
- They work with Textio to ensure inclusive job design and hiring.